Severity High Analysis Summary CVE-2020-3155 The vulnerability is due to a lack of validation of the SSL server certificate received when establishing a connection to a […]
Severity High Analysis Summary CVE-2020-3148 The vulnerability is due to insufficient CSRF protections in the web-based interface. An attacker could exploit this vulnerability by persuading a […]
Severity High Analysis Summary The Mailto ransomware has a new technique for process injection. In their article on the topic, researchers discuss the ransomware at a […]
Severity High Analysis Summary Firstly, a recent ATM malware is found searching for the factory Logical Service Names in order to target ATMs. Additionally, Mobile Banking […]
Severity High Analysis Summary Google Chrome could allow a remote attacker to bypass security restrictions, caused by insufficient policy enforcement in media. By persuading a victim […]
Severity High Analysis Summary Ongoing scans for Apache Tomcat servers unpatched against the Ghostcat vulnerability that allows potential attackers to take over servers have been detected […]
Severity High Analysis Summary A new campaign is found distributing the ProClient RAT that has advanced capabilities of a cyber espionage. This RAT is written in […]
Severity High Analysis Summary Lazarus has a long history of destructive cyber-attacks. Some more notable examples are the 2013 “Dark Seoul” attacks, the 2014 attack on […]
Severity High Analysis Summary A couple dozen documents have been found in the past few weeks, that execute the OSTAP javascript downloader. The documents make use […]